scieee AI-readable full text Open interactive document viewer

A standard architecture for TREs: why is it important in a federated world?

Simon, Li

Abstract

Background The Standard Architecture for Trusted Research Environments (SATRE), version 1.0, provided a baseline set of best-practice capabilities of relevance to TREs in the UK developed jointly with TRE operators and public representatives. It has requirements that TREs holding personal data should fulfil to demonstrate equivalence in a transparent manner. It was published in October 2023 and was quickly adopted by Trusted Research Environments (TREs) across the UK and beyond. The initial success of SATRE was due to two main factors: it was driven by an open-collaboration with a grassroots community, and it encapsulated the existing state of most TREs, as opposed to imposing a top-down view of what a TRE should be. This was primarily achieved through Collaboration Cafés – open events that anyone can attend – supported by other events to obtain input and feedback from the wider community. Independent communities have used SATRE as a starting point for federation projects including the NHS regional SDEs, the Scottish Safe Haven network, and the European Open Source Cloud ENTRUST network of federated TREs. Others have also asked for extensions to SATRE such as for natural language processing, or data tiering and classification. Finally, several groups planning to deploy new TREs had requested guidance on how to implement a new SATRE compliant TRE. Objectives Version 2 of SATRE, through the TREvolution Core Programme, incorporates guidance on TRE federation for the UK and beyond. Supporting these needs is critical to ensuring the community remains involved in SATRE, and will not result in multiple competing or conflicting standards. It establishes a long-term sustainable governance and accreditation model. The new version also allows for infrastructure that was, and still is, under active development, with limited existing best-practice. This has required a different approach to that taken for version 1.0, with a layered specification model providing not only architectural but also implementation guidance. A significant outcome of the SATRE work is a specification for TREs based on Kubernetes; a popular, flexible and standard open-source platform for managing containerised workloads and services which is already making in-roads into the TRE ecosystem. Encouraging Kubernetes as a common – community owned – infrastructure baseline allows components to be shared across implementations where practical, and provides a solution for independent TREs to be part of a federated network. Finally, we provide an initial version of a technical specification-compliant vendor-neutral reference TRE, called “K8TRE”. This is suitable for pilot deployments, and development continues to make it production ready. K8TRE is fully open-source and can be deployed on private infrastructure, or in the public cloud, with minimal adaptation.

Full text

Simon Li Health Informatics Centre, University of Dundee HDR UK A standard architecture for TREs: why is it important in a federated world? Conflicts of Interest Disclosure(s) Dr Simon Li •Financial Interest: Health Informatics Centre, University of Dundee -HIC has received funding from UKRI, ScotGov, NHS, Charities and Industry over past 20 years The Health Informatics Centre (HIC) https://www.dundee.ac.uk/hic | 3 •Including electronic health records and medical images (170+ datasets covering 2.1m people's records since 2004) •We're data curators/processors on behalf of data controllers •And are part of the Scottish Safe Haven network | 4 We provide access to national healthcare data for researchers Background | 5 We’re not making use of our existing data | 6 But how can we use this data safely and securely? Can undiagnosed heart failure be detected from routine medical records? | 7 Example use-case Should we let them copy it to their own laptops? No! | 8 How do we securely give researchers access to the data? https://media.northernrailway.co.uk/news/the-hamster-the-wig-and-the-cupboard-northern-customers-reportmore-than-32-600-items-of-lost-property •A locked-down compute environment with access to the data but no ability to copy data out | 9 We can provide an environment that minimises the risk of leaking sensitive data •Along with background checks on the researcher and what they want to do, minimizing data that they receive, and verification that their analysis results will be safe to take out of the environment Adding Federation to SATRE | 17 Enabling federated data analysis in TREs is complicated! What should be in SATRE v2 to support federated TREs? For example: •Overall governance of TREs •Different models of analysis? •Roles and responsibilities •TRE Zones: Secure Data Zone, Research Analytics Zone •…. We’re incorporating existing work and standards | 18 SATRE v1 is the starting point for federation https://zenodo.org/records/14192786 We are simultaneously defining the standard for federation and demonstrating in production as part of TREvolution https://dareuk.org.uk/trevolution/ | 19 Federation in SATRE: backed by implementations Open-source tools and standards, available to try now Accreditation and Governance But what does that mean? To help reach consensus in the community we have published an alignment table: •ISO27001 •NHS Data Security and Protection Toolkit •Digital Economy Act •SDE Accreditation •Cyber Essentials | 21 There is a lot of demand for SATRE to become a more formal accreditation “SATRE Centric Control Alignment Table for Trusted Research Environments” https://zenodo.org/records/16837077 Who’s involved? https://bit.ly/hdruk25 •Links from this talk •More information on how to get involved | 23 Get involved! SATRE is created and owned by the TRE community Who’s involved in this work? https://bit.ly/hdruk25 Public involvement & engagement: Antony Chuter Jill Hampton Judith Fisher Katie Oldfield